CVE-2024-10238: Smci Mbd-x12dpg-OA6

High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.

A security issue in the firmware image verification implementation at Supermicro MBD-X12DPG-OA6. An attacker can upload a specially crafted image that will cause a stack overflow is caused by not checking fld->used_bytes.

Affected products

  • Smci Mbd-x12dpg-OA6: version 1.04.16 only

Published 2025-02-04. Last modified 2026-06-17.